Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Financially Motivated

Snarky Spider

Also known asSnarky Spider

Snarky Spider is a financially motivated threat group affiliated with The Com and closely aligned with Scattered Spider. It is also tracked as O-UNC-025 and UNC6661. CrowdStrike reported the group has been active since at least October 2025 and primarily targets U.S.-based organizations across sectors including academic, aviation, retail, hospitality, automotive, financial services, legal, and technology, as well as multiple critical infrastructure sectors. The group conducts rapid data theft and extortion campaigns, often operating almost exclusively within trusted SaaS environments such as Google Workspace, HubSpot, Microsoft SharePoint, and Salesforce to minimize endpoint visibility and accelerate impact. Its intrusion chain relies heavily on voice phishing and social engineering, including impersonation of IT support or help desk personnel via phone calls, as well as text messages and emails, to direct victims to adversary-in-the-middle phishing pages that mimic legitimate single sign-on or identity provider portals. These pages capture credentials, MFA codes, session keys, or tokens, allowing access to the victim identity provider and lateral movement across SSO-integrated SaaS applications. After compromise, Snarky Spider establishes persistence by removing existing MFA devices, registering attacker-controlled devices, and deleting or filtering security notifications through inbox rules. The content specifically states that Snarky Spider almost exclusively enrolls Genymobile Android emulators for connected-device management. The group also scrapes internal employee directories to identify privileged users, targets high-privileged accounts through additional social engineering, searches SaaS platforms for high-value information, and can begin high-volume data exfiltration in under an hour. The group uses living-off-the-land techniques and residential proxy or VPN services to conceal origin and evade IP-based detection; providers named in the content include Mullvad, Oxylabs, NetNut, 9Proxy, Infatica, and NSOCKS. Its operations are focused on data theft for extortion, with reported ransom demands often reaching seven figures. The content also states that some victims have faced follow-on harassment including swatting, and some non-paying victims have experienced DDoS attacks. CrowdStrike described Snarky Spider as a native English-speaking crew and as part of a new generation using much of Scattered Spider’s playbook.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics27 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589
Gather Victim Identity Information
T1598×2
Phishing for Information
T1598.004
Spearphishing Voice
TA0001
Initial Access
2 techniques
T1078×3
Valid Accounts
T1566
Phishing
T1566.004×3
Spearphishing Voice
TA0003
Persistence
2 techniques
T1078×3
Valid Accounts
T1556×4
Modify Authentication Process
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
TA0005
Stealth
2 techniques
T1070×3
Indicator Removal
T1078×3
Valid Accounts
TA0112
Defense Impairment
1 technique
T1556×4
Modify Authentication Process
TA0006
Credential Access
4 techniques
T1539×2
Steal Web Session Cookie
T1556×4
Modify Authentication Process
T1557×2
Adversary-in-the-Middle
T1649×2
Steal or Forge Authentication Certificates
TA0007
Discovery
2 techniques
T1087
Account Discovery
T1526
Cloud Service Discovery
TA0009
Collection
3 techniques
T1114
Email Collection
T1114.003×2
Email Forwarding Rule
T1213
Data from Information Repositories
T1557×2
Adversary-in-the-Middle
TA0011
Command and Control
1 technique
T1090
Proxy
T1090.003×2
Multi-hop Proxy
TA0010
Exfiltration
2 techniques
T1537
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
1 technique
T1498×2
Network Denial of Service
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping20

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.